SlowMist details Liquid exploit that minted 3,998.5 L-BTC without collateral

SlowMist details Liquid exploit that minted 3,998.5 L-BTC without collateral

N
News Editor
2026-09-11 12:20:57
SlowMist said on X that Liquid Network was hit by a Rangeproof verification cache key collision exploit on Sept. 6. According to the security firm, the attacker minted about 3,998.5 L-BTC without any corresponding BTC peg-in, then converted the tokens into Bitcoin on the main network through peg-out transactions within minutes. After the incident, about 3,400 BTC was returned to the Liquid federation peg wallet, while roughly 598.5 BTC remains under the attacker’s control. SlowMist said the flaw came from the way Elements constructed Rangeproof verification cache keys by concatenating multiple variable-length fields without adding length prefixes. That allowed different parameter combinations to produce the same cache key. By crafting transactions to trigger a cache collision, the attacker caused nodes to hit a previously cached “verification passed” result, skipping both secp256k1_rangeproof_verify and the minimum amount check. SlowMist added that it has traced the Bitcoin-side fund flows and completed its analysis of the incident.

Odaily reported that SlowMist disclosed on X that Liquid Network was exploited on Sept. 6 through a Rangeproof verification cache key collision flaw.

According to SlowMist, the attacker minted about 3,998.5 L-BTC without any corresponding BTC peg-in, then converted the assets into Bitcoin on the main network through peg-out transactions within minutes.

After the incident, about 3,400 BTC was returned to the Liquid federation peg wallet. Roughly 598.5 BTC is still controlled by the attacker.

How the flaw worked

SlowMist said the issue stemmed from Elements’ Rangeproof verification cache key design. When multiple variable-length fields were concatenated, no length prefixes were added, creating a situation where different parameter combinations could produce the same cache key.

The attacker crafted transactions that triggered a cache collision, causing nodes to hit a cached “verification passed” result. That let the transactions bypass both secp256k1_rangeproof_verify and the minimum amount check, leading nodes to accept outputs that were not backed by real assets and complete the L-BTC minting process.

SlowMist said it has traced the Bitcoin-side fund flows and completed its analysis of the incident.

This article was originally published by Bit.Fan. For more cryptocurrency news and market insights, visit www.bit.fan.
200

Disclaimer:

The market information, project data, and third-party content displayed on this platform are for industry information sharing only and do not constitute any form of investment advice or return commitment.

Cryptocurrency trading carries high risks. Users should fully assess their risk tolerance and make independent decisions. All profits, losses, and legal responsibilities are borne by the users themselves.